Sr.Manager, Information Security Engineer

Federal Home Loan Bank of Chicago
Chicago, IL, United States
1 day ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$151,025.0 - $265,525.0
Working hours
Regular working hours

Tech stack

Microsoft Access Application Programming Interfaces (APIs) Amazon Web Services Data Analysis Software System Penetration Testing Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Decision Support Systems
+20 more
Executive Information Systems Identity and Access Management Key Management Network Security Network Segmentation Cloud Services Zero Trust Network Access Security Information and Event Management Software Vulnerability Management SSL Certificate Management Data Logging Software Security Technical Debt Infrastructure Automation Frameworks Information Technology Data Management Devsecops Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

The Senior Manager, Information Security Engineering leads the design, engineering, implementation, and lifecycle management of technical security controls that protect the Bank’s systems, identities, applications, data, cloud services, and customer-facing capabilities. The role reports to the Chief Information Security Officer, and manages a blended team of employees and contractors, establishes engineering priorities and standards, and translates security requirements into scalable, supportable, and measurable technology solutions. The position aligns the security tool portfolio and engineering roadmap to the NIST Cybersecurity Framework (CSF), Bank policy, risk appetite, architecture standards, and applicable regulatory expectations. How you’ll make an impact

  • Builds and sustains a resilient defense-in-depth control environment across on-premises, AWS, Microsoft Azure, SaaS, endpoint, network, identity, application, and data platforms.
  • Converts cybersecurity risk, policy, and architecture requirements into practical technical controls, engineering patterns, automation, and operational guardrails.
  • Improves control effectiveness, reliability, coverage, and transparency through disciplined engineering practices and outcome-oriented metrics.* Develops security engineering talent and creates clear accountability across employees, contractors, vendors, and technology partners.
  • Enhances the Bank’s resilience by delivering secure, scalable, and reliable security controls that protect critical systems, data, and customer services.
  • Drives risk reduction and regulatory readiness through the implementation of modern security capabilities, automation, and governance aligned with industry and regulatory standards.
  • Accelerates security maturity and operational excellence by leading high-performing engineering teams, optimizing security investments, and providing measurable improvements in control effectiveness and business protection. What you can expect

  • Lead, coach, and develop security engineering employees and contractors. Set clear objectives, allocate work, manage capacity, provide feedback, support performance and career development, and promote an inclusive, accountable, and collaborative culture.
  • Own the security engineering strategy, operating model, multi-year roadmap, backlog, budget inputs, workforce plan, vendor relationships, and delivery commitments. Balance strategic initiatives, control maintenance, technical debt, and urgent risk reduction.
  • Align security engineering capabilities, tools, and technical controls to the NIST CSF functions and categories. Maintain traceability from risks and requirements to control design, implementation, evidence, ownership, and measurement.
  • Partner with Security Architecture, Security Operations, Threat and Incident Response, Identity and Access Management, Security Advisory and Analytics, IT Risk and Compliance, Enterprise Architecture, Infrastructure, Cloud, Network, and Application teams to design and implement effective controls.
  • Assist control owners and engineering teams with the development, documentation, implementation, testing, and continuous improvement of preventive, detective, responsive, and recovery-oriented technical controls.
  • Provide engineering leadership for security technologies supporting endpoint and workload protection, identity and privileged access, cloud security, network security, security monitoring and logging, data protection, vulnerability management, application security, certificate and secrets management, email and collaboration security, and security automation.
  • Direct security engineering for AWS and Microsoft Azure environments, including secure configuration baselines, native security services, identity and access controls, logging and monitoring, encryption and key management, network segmentation, workload protection, and automated policy enforcement.
  • Establish standards for security tool selection, architecture, configuration, integration, lifecycle management, resilience, supportability, and decommissioning. Identify tool overlap, coverage gaps, operational dependencies, and opportunities for consolidation or automation.
  • Define engineering quality practices, including peer review, change control, infrastructure as code, testing, documentation, secure configuration, release readiness, rollback planning, and handoff to operational support teams.
  • Develop and maintain technical standards, baseline security configurations, reference architectures, procedures, engineering runbooks, control narratives, and evidence required for governance, risk, audit, and regulatory review.
  • Develop meaningful metrics and dashboards that measure control coverage, control health and effectiveness, engineering delivery, reliability, automation, technical debt, risk reduction, and service performance. Use results to prioritize investment and drive continuous improvement.
  • Provide concise reporting to security and technology leadership on roadmap progress, material risks, exceptions, dependencies, resource constraints, control performance, and recommended decisions.
  • Support security incidents, investigations, vulnerability remediation, audit findings, risk acceptances, penetration testing, and threat-driven improvements by coordinating engineering analysis and sustainable corrective actions.
  • Participate in technology planning and design reviews to ensure security requirements are incorporated early and implemented in a manner that supports business objectives and customer needs.
  • Provide technical escalation and decision support for complex security control and tooling issues. Coordinate off-hours support when required for critical incidents or significant production changes.
  • Perform other duties as assigned. What you’ll bring, + Develops talent through coaching, stretch assignments, succession planning, recognition, and timely constructive feedback.

  • Promotes engineering discipline, psychological safety, responsible challenge, documentation, knowledge sharing, and continuous learning.
  • Demonstrates integrity, risk ownership, customer focus, collaboration, and responsible stewardship of Bank resources. Success Measures

  • Improved security-control coverage, health, effectiveness, reliability, and evidence quality.
  • Timely delivery of prioritized engineering roadmap commitments and sustainable remediation of material risks and findings.* Reduced manual effort, repeated incidents, tool overlap, unsupported configurations, and security technical debt through standardization and automation.
  • Clear NIST CSF traceability for the security engineering portfolio and technical controls.
  • Actionable metrics that enable risk-based decisions and demonstrate security and operational outcomes.
  • Effective workforce capacity, talent development, contractor performance, vendor accountability, and stakeholder satisfaction.

Requirements

  • Bachelor’s degree in cybersecurity, information technology, engineering, computer science, or a related discipline, or equivalent relevant experience.
  • Typically 8 or more years of progressive experience in cybersecurity, security engineering, cloud security, infrastructure engineering, or a related technology field, including demonstrated leadership of technical teams and complex initiatives.
  • Experience managing a blended workforce of employees, contractors, consultants, and technology vendors.
  • Hands-on or leadership experience designing, implementing, and operating security controls in AWS and Microsoft Azure environments.
  • Experience aligning security capabilities or controls to the NIST CSF and translating risk, policy, or regulatory requirements into implementable technical solutions.
  • Experience developing security metrics, control-health reporting, executive dashboards, and evidence used to support risk, audit, or regulatory processes.
  • Financial services or other regulated-industry experience preferred.
  • Industry certification such as CISSP, CISM, CCSP, GIAC, AWS Security Specialty, or Microsoft cybersecurity certification preferred.
  • Strong knowledge of security architecture and engineering principles, defense in depth, zero trust, cloud shared-responsibility models, secure configuration, and secure system lifecycle practices.
  • Working knowledge of AWS and Azure security services, cloud identity, workload protection, logging, monitoring, encryption, key and secrets management, network security, and policy automation.
  • Broad familiarity with security platforms and capabilities such as SIEM, EDR/XDR, CSPM/CNAPP, vulnerability management, PAM, IAM, DLP, CASB/SSE, WAF, email security, certificate management, secrets management, SAST/DAST/SCA, and breach-and-attack simulation.
  • Ability to evaluate technical control design and effectiveness, identify root causes and dependencies, and create practical remediation roadmaps.
  • Ability to develop measures that distinguish activity, service performance, control coverage, control health, risk exposure, and business outcomes.
  • Experience with automation and scripting, APIs, infrastructure as code, CI/CD pipelines, and DevSecOps practices preferred.* Strong program, portfolio, vendor, financial, and workforce management skills.
  • Excellent written, verbal, presentation, visualization, listening, negotiation, and stakeholder-management skills.
  • Ability to communicate complex technical and risk topics clearly to technical teams, business leaders, auditors, and executive stakeholders.
  • Sound judgment, attention to detail, personal accountability, and the ability to lead through ambiguity, competing priorities, incidents, and change. Leadership Expectations

  • Sets a clear direction and connects team priorities to enterprise strategy, security risk, and measurable outcomes.
  • Creates role clarity and effective ways of working across employees, contractors, vendors, and partner teams.

Benefits & conditions

At the Federal Home Loan Bank of Chicago, employees come first - that’s why we offer a highly competitive compensation and bonus package, and access to a comprehensive benefits program designed to meet the needs of our employees.

  • Collaborative, in-office operating model

  • Retirement program (401k and Pension)

  • Medical, dental and vision insurance

  • Lifestyle Spending Account

  • Competitive PTO plan, $151,025.00 - $265,525.00 The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we may also consider your experience, and other job-related factors. In addition to the base salary, we offer a comprehensive benefits package which can be found here: https://hrportal.ehr.com/fhlbc

About the company

Our mission at FHLBank Chicago: To partner with our members in Illinois and Wisconsin to provide them competitively priced funding, a reasonable return on their investment, and support for their community investment activities. Simply said, we’re a bank for banks and other financial institutions, focused on being a strategic partner for our members and working together to reinvest in our communities, from urban centers to rural areas. Created by Congress in 1932, FHLBank Chicago is one of 11 Federal Home Loan Banks, government sponsored in support of mortgage lending and community investment. What it’s like to work here At FHLBank Chicago, we bring people together. We are committed to a high performing, engaged workforce, and to supporting the communities we serve across Illinois and Wisconsin. Our Buddy Program pairs new hires with tenured employees to guide their onboarding. Our professional development and training opportunities through upskilling, mentorship programs, and tuition reimbursement allow employees to grow their career with us. Our collaborative, in-office operating model brings teams together to foster innovation, connection, and shared success. To support balance and flexibility, employees are provided an allocation of remote days to use as needed throughout the year. What you’ll do

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella · World Congress 2023

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all